
DGFV338 ProSafe Wireless ADSL Modem VPN Firewall Router Reference Manual
Security and Firewall Protection
4-27
v1.0, May 2008
•
Check the box adjacent to the binding to be deleted and click
delete,
or
•
Click
select all
to select all the bindings and click
delete
.
Configuring Port Triggering
Port triggering allows some applications to function correctly that would otherwise be partially
blocked by the firewall when the router is in NAT mode. Some applications require that when
external devices connect to them, they receive data on a specific port or range of ports. The router
must send all incoming data for that application only on the required port or range of ports. Using
this feature requires that you know the port numbers used by the application.
Port triggering allows computers on the private network (LAN) to request that one or more ports
be forwarded to them. Unlike basic port forwarding which forwards ports to only one
preconfigured IP address, port triggering waits for an outbound request from the private network
on one of the defined outgoing ports. It then automatically sets up forwarding to the IP address that
sent the request. When the application ceases to transmit data over the port, the router waits for a
timeout interval and then closes the port or range of ports, making them available to other
computers on the private network.
Once configured, port triggering operates as follows:
1.
A PC makes an outgoing connection using a port number defined in the Outgoing Port
Triggering table.
2.
The ProSafe DGFV338 records this connection, opens the incoming port or ports associated
with this entry in the Incoming Port Triggering table, and associates them with the PC.
3.
The remote system receives the PC’s request and responds using the different port numbers
that you have now opened.
4.
This router matches the response to the previous request, and forwards the response to the PC.
Without Port Triggering, this response would be treated as a new connection request rather than a
response. As such, it would be handled in accordance with the inbound service rules.
Note these restrictions with Port Triggering:
•
Only one PC can use a Port Triggering application at any time.